Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 6.5 CVE-2022-36896 A missing permission check in Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.12 and earlier allows attackers with Overa… Compuware Source Code Download For Endevor\, Pds\, And Ispw after 2.0.12 Fix from $1,6002022-07-27 HIGH 7.5 CVE-2022-36883EPSS 6% A missing permission check in Jenkins Git Plugin 4.11.3 and earlier allows unauthenticated attackers to trigger builds of jobs configured to use an a… Git after 4.11.3 Fix from $1,9502022-07-27 HIGH 7.5 CVE-2021-33057 The QQ application 8.7.1 for Android and iOS does not enforce the permission requirements (e.g., android.permission.ACCESS_FINE_LOCATION) for determi… Qq No fix yet Fix from $1,9502022-07-26 MEDIUM 5.3 CVE-2021-32504 Unauthenticated users can access sensitive web URLs through GET request, which should be restricted to maintenance users only. A malicious attacker c… Ftmg Firmware 2.8+ Fix from $1,6002022-07-19 MEDIUM 5.3 CVE-2022-2108 The plugin Wbcom Designs – BuddyPress Group Reviews for WordPress is vulnerable to unauthorized settings changes and review modification due to missi… Buddypress Group Reviews 2.8.4+ Fix from $1,6002022-07-18 MEDIUM 5.5 CVE-2022-20225 In getSubscriptionProperty of SubscriptionController.java, there is a possible read of a sensitive identifier due to a missing permission check. This… Android Patch available Fix from $1,6002022-07-13 MEDIUM 5.4 CVE-2022-31597 Within SAP S/4HANA - versions S4CORE 101, 102, 103, 104, 105, 106, SAPSCORE 127, the application business partner extension for Spain/Slovakia does n… S\/4hana Mitigation only Fix from $1,6002022-07-12 CRITICAL 9.8 CVE-2022-1245 A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid ac… Keycloak 18.0.0+ Fix from $2,3002022-07-08 MEDIUM 5.5 CVE-2022-21763 In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure wit… Android Mitigation only Fix from $1,6002022-07-06 MEDIUM 5.5 CVE-2022-21764 In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure wit… Android Mitigation only Fix from $1,6002022-07-06 HIGH 7.8 CVE-2022-21777 In Autoboot, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additi… Android Mitigation only Fix from $1,9502022-07-06 MEDIUM 6.5 CVE-2022-34810 A missing check in Jenkins RQM Plugin 2.8 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials store… Rqm after 2.8 Fix from $1,6002022-06-30 MEDIUM 6.5 CVE-2022-34794 Missing permission checks in Jenkins Recipe Plugin 1.2 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacke… Recipe after 1.2 Fix from $1,6002022-06-30 MEDIUM 6.5 CVE-2022-34781 Missing permission checks in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allow attackers with Overall/Read permission to connect to an att… Xebialabs Xl Release after 22.0.0 Fix from $1,6002022-06-30 HIGH 8.1 CVE-2022-1903EPSS 9% The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing nonce and authorization checks i… Armember 3.4.8+ Fix from $1,9502022-06-27 HIGH 8.1 CVE-2022-1572 The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to any authenticated users such a… Html2wp after 1.0.0 Fix from $1,9502022-06-27 CRITICAL 9.8 CVE-2022-1574EPSS 12% The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result,… Html2wp after 1.0.0 Fix from $2,3002022-06-27 CRITICAL 9.1 CVE-2022-1521 LRM does not implement authentication or authorization by default. A malicious actor can inject, replay, modify, and/or intercept sensitive data. Local Run Manager after 3.1 Fix from $2,3002022-06-24 MEDIUM 5.7 CVE-2022-34212 A missing permission check in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attackers with Overall/Read permission to send an HTTP POST… Vrealize Orchestrator after 3.0 Fix from $1,6002022-06-23 MEDIUM 6.5 CVE-2022-34201 A missing permission check in Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier allows attackers with Overall/Read permission to connect to a… Convertigo Mobile Platform after 1.1 Fix from $1,6002022-06-23 MEDIUM 6.5 CVE-2022-34210 A missing permission check in Jenkins ThreadFix Plugin 1.5.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-spec… Threadfix after 1.5.4 Fix from $1,6002022-06-23 CRITICAL 9.8 CVE-2021-26637 There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-300, GCM-300, so unauthorized… Sihas Sgw 300 Firmware Mitigation only Fix from $2,3002022-06-23 MEDIUM 5.5 CVE-2022-23055 In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality. A low privileged attacker… Erpnext 13.1.0+ Fix from $1,6002022-06-22 MEDIUM 6.5 CVE-2022-31095 discourse-chat is a chat plugin for the Discourse application. Versions prior to 0.4 are vulnerable to an exposure of sensitive information, where an… Discourse Chat 0.4+ Fix from $1,6002022-06-21 HIGH 7.5 CVE-2022-33913 In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php with no permission check. Mahara 21.04.6 / 21.10.4+ Fix from $1,9502022-06-20 HIGH 8.1 CVE-2021-46820 Arbitrary File Deletion vulnerability in XOS-Shop xos_shop_system 1.0.9 via current_manufacturer_image parameter to /shop/admin/categories.php Xos Shop System No fix yet Fix from $1,9502022-06-16 HIGH 8.1 CVE-2021-37764 Arbitrary File Deletion vulnerability in XOS-Shop xos_shop_system 1.0.9 via current_manufacturer_image parameter to /shop/admin/manufacturers.php. Xos Shop System Mitigation only Fix from $1,9502022-06-16 MEDIUM 5.3 CVE-2022-20736 A vulnerability in the web-based management interface of Cisco AppDynamics Controller Software could allow an unauthenticated, remote attacker to acc… Appdynamics Controller 21.4.7+ Fix from $1,6002022-06-15 MEDIUM 5.5 CVE-2022-20200 In updateApState of SoftApManager.java, there is a possible leak of hotspot state due to a missing permission check. This could lead to local informa… Android Mitigation only Fix from $1,6002022-06-15 HIGH 7.8 CVE-2022-20204 In registerRemoteBugreportReceivers of DevicePolicyManagerService.java, there is a possible reporting of falsified bug reports due to a missing permi… Android Mitigation only Fix from $1,9502022-06-15